CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
305 | CVE-1999-0306 | Candidate | buffer overflow in HP xlock program. | Proposed (19990714) | ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Prosser | NOOP(1) Shostack | REJECT(1) Christey | Prosser> This is another of those with multiple affected OSs. | Refs: CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt, | HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150 | Christey> XF:hp-xlock points to SGI:19970502-02-PX which says this is | the same problem as in CERT:CA-97.13, which is CVE-1999-0038. | View |
4737 | CVE-2002-0345 | Candidate | Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServerparams registry key, which could allow an attacker to gain privileges. | Proposed (20020502) | ACCEPT(2) Frech, Prosser | NOOP(4) Cole, Cox, Foat, Wall | Prosser> This was verified and responded to via BugTraq and fixed via | LiveUpdate http://online.securityfocus.com/archive/1/259559 | View |
2922 | CVE-2001-0101 | Candidate | Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command. | Modified (20020222-01) | ACCEPT(4) Baker, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Prosser> TURBO:TLSA2000024-1 | http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:fetchmail-authenticate-gssapi(7455) | View |
2508 | CVE-2000-0939 | Candidate | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart. | Proposed (20001129) | ACCEPT(2) Frech, Mell | NOOP(1) Cole | REJECT(1) Renaud | Renaud> SWAT makes this DoS easier to perform, but actually, it is an inetd | problem, not a swat problem. | View |
286 | CVE-1999-0287 | Candidate | Vulnerability in the Wguest CGI program. | Proposed (19990714) | MODIFY(2) Frech, Shostack | NOOP(4) Blake, Levy, Northcutt, Wall | REJECT(2) Baker, Christey | Shostack> allows file reading | Frech> XF:http-cgi-webcom-guestbook | Christey> CVE-1999-0287 is probably a duplicate of CVE-1999-0467. In | NTBUGTRAQ:19990409 Webcom"s CGI Guestbook for Win32 web servers | Mnemonix says that he had previously reported on a similar | problem. Let"s refer to the NTBugtraq posting as | CVE-1999-0467. We will refer to the "previous report" as | CVE-1999-0287, which could be found at: | http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html | | 0287 describes an exploit via the "template" hidden variable. | The exploit describes manually editing the HTML form to | change the filename to read from the template variable. | | The exploit as described in 0467 encodes the template variable | directly into the URL. However, hidden variables are also | encoded into the URL, which would have looked the same to | the web server regardless of the exploit. Therefore 0287 | and 0467 are the same. | Christey> BID:2024 | View |
Page 20927 of 20943, showing 5 records out of 104715 total, starting on record 104631, ending on 104635